CVE-2026-27285: InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27285?
CVE-2026-27285 has a severity that could lead to application denial-of-service.
How do I fix CVE-2026-27285?
Updating Adobe InDesign Desktop to version 21.3 or later will mitigate the effects of CVE-2026-27285.
What versions of Adobe InDesign Desktop are affected by CVE-2026-27285?
CVE-2026-27285 affects Adobe InDesign Desktop versions 20.5.2 and 21.2 and earlier.
What type of vulnerability is CVE-2026-27285?
CVE-2026-27285 is categorized as a Heap-based Buffer Overflow vulnerability.
What are the potential impacts of CVE-2026-27285?
Exploitation of CVE-2026-27285 can lead to application crashes and service disruption.